Senior IdAM Engineer IRES - SSFB/HSV/FBEL

Amentum•Colorado Springs, CO
•$175,000 - $220,000•Onsite

About The Position

As a Senior IdAM Engineer supporting the Next Generation Environment (NGE) on the Integrated Research and Development for Enterprise Solutions (IRES) contract, you will serve as a senior technical contributor responsible for engineering, deploying, automating, securing, and sustaining the Identity, Credential, and Access Management (IdAM / ICAM) ecosystem underpinning the Missile Defense Agency’s (MDA) unified digital environment. In this role, you will help advance NGE’s hybrid and multi-cloud identity modernization strategy by implementing robust Identity Governance and Administration (IGA) workflows, federation and Single Sign-On (SSO) services, enterprise directory integrations, and DoD/NSS Public Key Infrastructure (PKI) aligned with the Zero Trust Security Model. You will work across engineering, cybersecurity, hybrid cloud, infrastructure, contract consortium performers, and Government stakeholder teams to deliver resilient identity services across on-premises and cloud-hosted mission environments. You will play a key role in standardizing identity lifecycle automation, enhancing authentication security, eliminating credential risks, strengthening access controls, and ensuring continuous compliance with DoD, DISA, and MDA security requirements.

Requirements

  • Must have 12, or more, years of general (full-time) work experience (May be reduced with completion of advanced education)
  • Must have 6, or more, years of dedicated Identity, Credential, and Access Management (IdAM / ICAM) experience.
  • Must have 1, or more, years of experience in technical leadership, mentoring, or engineering management roles.
  • Must have direct experience supporting the IRES contract or previous technical experience supporting the Missile Defense Agency (MDA).
  • Must have demonstrated, hands-on, engineering proficiency across enterprise identity solutions, specifically:
  • Must have a combination of experience, or familiarity, with the following:
  • SailPoint IdentityIQ (IIQ) (deployments, lifecycle workflows, rules, and connectors).
  • PingIdentity PingFederate (SAML, OAuth2, OIDC, MFA federation).
  • Microsoft Directory Services (AD DS, AD FS).
  • Cloud Identity Management (Microsoft Entra ID, AWS IAM).
  • DoD / NSS Public Key Infrastructure (PKI) (Certificate Authorities, validation, and token integration).
  • Must hold a current DoW 8140/8570 IAT Level II or higher certification (e.g., Security+ CE, CySA+, CASP+ CE, CISSP).
  • Must have an active DoW Secret security clearance with the ability to obtain a Top Secret clearance (or active Top Secret).
  • Must have an active DoW Secret Security Clearance

Nice To Haves

  • Have an active DoW Top Secret clearance.
  • Have a Bachelor’s degree, or higher, in Computer Science, Information Technology, or Cybersecurity.
  • Professional certifications in core tools:
  • SailPoint Certified IdentityIQ Engineer / Architect
  • Ping Identity Certified Professional
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • AWS Certified Security – Specialty
  • Have experience integrating identity solutions with Privileged Access Management (PAM) platforms (e.g., CyberArk) and enterprise ITSM systems (e.g., ServiceNow).
  • Have experience with Model-Based Systems Engineering (MBSE) concepts and Agile/SAFe methodologies within DoD/MDA environments.

Responsibilities

  • Implement, deploy, configure, and sustain SailPoint IdentityIQ (IIQ) solutions, including Operations & Maintenance (O&M), platform upgrades, capability enhancements, and enterprise application onboarding.
  • Design and customize identity lifecycle management workflows (joiner, mover, leaver), certification campaigns, role-based/attribute-based access controls (RBAC/ABAC), custom Java rules, and compliance reporting.
  • Engineer, deploy, and maintain PingIdentity PingFederate services to enable secure, federated Single Sign-On (SSO) across enterprise and mission partner applications.
  • Lead application onboarding and integration utilizing modern authentication and authorization protocols, including SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), and phishing-resistant Multi-Factor Authentication (MFA).
  • Implement and sustain secure identity and access architectures across hybrid multi-cloud environments, including Microsoft Entra ID (Azure AD) and Amazon Web Services (AWS IAM and AWS IAM Identity Center) operating within DoD IL5/IL6 boundaries.
  • Ensure secure synchronization, conditional access policy enforcement, and seamless identity interoperability between on-premises domains and cloud service providers.
  • Configure, optimize, and administer Microsoft Directory Services, including Active Directory Domain Services (AD DS) and Active Directory Federation Services (AD FS), maintaining high availability and schema integrity.
  • Maintain Kerberos, LDAP/S, and federated trust configurations across complex multi-forest and segmented enterprise environments.
  • Deploy, maintain, and support DoD and National Security Systems (NSS) Public Key Infrastructure (PKI) components, including Certificate Authorities (CAs), hardware tokens (CAC/PIV/SIPR tokens), Certificate Validation services (OCSP/CRL), and certificate lifecycle management.
  • Ensure cryptographic enforcement and certificate-based authentication across all network boundaries, endpoints, and server infrastructure.
  • Implement dynamic, identity-centric security policies and controls supporting the DoD Zero Trust Strategy and NIST SP 800-207.
  • Harden identity platforms and services in accordance with DISA STIGs, Risk Management Framework (RMF), and MDA cybersecurity requirements to support continuous Authorization to Operate (cATO).
  • Collaborate with multi-contractor consortium performers, systems engineers, network architects, DevSecOps teams, and Government personnel to standardize identity interfaces and integration protocols.
  • Serve as an identity integration focal point during Joint Interoperability Test events, cross-domain coordination, and enterprise cutovers.
  • Develop and maintain automated provisioning scripts, API integrations (SCIM, REST), and administrative routines utilizing PowerShell, Bash, Python, or Java to streamline identity operations and eliminate manual configuration drift.
  • Author and maintain comprehensive engineering deliverables, including Low-Level Designs (LLDs), Interface Control Documents (ICDs), standard operating procedures (SOPs), deployment runbooks, and test/validation plans.
  • Research and assess emerging IdAM/ICAM technologies, cloud identity features, and PAM/IGA enhancements to optimize security posture, scalability, and user experience across NGE.
  • Provide technical status, risk analysis, and engineering recommendations to program leadership and Government stakeholders.
  • Translate complex identity, PKI, and federation requirements into actionable engineering plans and mission outcomes.

Benefits

  • Health, dental, and vision insurance
  • Paid time off and holidays
  • Retirement benefits (including 401(k) matching)
  • Educational reimbursement
  • Parental leave
  • Employee stock purchase plan
  • Tax-saving options
  • Disability and life insurance
  • Pet insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service